Cryptographic Weakness in Omada Adoption Protocol by TP-Link
CVE-2025-15627

6.9MEDIUM

What is CVE-2025-15627?

A cryptographic flaw exists in the Omada adoption protocol, which utilizes hard-coded cryptographic keys for establishing trust and securing authentication communications between controllers and managed devices during the adoption process. This vulnerability may allow attackers to impersonate legitimate controllers or managed devices, potentially leading to unauthorized access to sensitive adoption-related data and communications.

Affected Version(s)

Omada Access Points 0

Omada Controllers 0

Omada Gateways 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Stanislav Dashevskyi and Francesco La Spina of Forescout Technologies
.